# Malware found in node-red project

**URL:** <https://discourse.nodered.org/t/malware-found-in-node-red-project/98799>\
**Category:** General\
**Tags:** security, docker\
**Created:** [23 August 2025 10:10 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799 "2025-08-23T10:10:14Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 10:10 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/1 "2025-08-23T10:10:14Z")

</div>

I found malicious code in my project. It was not in my repository, not even proof It has been active as it errored an update. The prior edit of the project was 18 hours ago (no issues) and I updated portainer 2 days ago. I am still clueless about the source.

The relevant code

**code removed by moderator for safety reasons**

I blocked the IP address 18.228.3.224:4782 and any advise or analysis is welcome

GTP’s summary:

**Tab 1** (`z = 84c7fdf3-ae46-4368-a7a2-cfdbd3c2e72c`)

1. **Trigger node (`kick`)** → fires once at startup.

2. **Exec node (`cpu-count`)** → tries to determine CPU count and then **opens a reverse shell** :

3. **Function node (`storeLast`)** → saves CPU count to flow context.

4. **HTTP GET endpoint (`/health/cpu`)** → returns CPU count and timestamp via `readLast` → `http response`.

**Summary:** This tab mixes a legitimate CPU-checking/reporting function with a **malicious reverse shell** (`cpu-count`).

* * *

### **Tab 2** (`z = 846d1d833fcd3831`)

1. **Trigger node** → fires once at startup.

2. **Exec node (`example flow 001`)** → immediately runs a Node.js reverse shell:

**Summary:** This tab is **purely malicious** , designed to give the attacker a backdoor.

---

<div class="post-metadata">

**Author:** ![Trying\_to\_learn](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/trying_to_learn/32/28400_2.png) [@Trying\_to\_learn](https://discourse.nodered.org/u/Trying_to_learn)\
**Post date:** [23 August 2025 10:19 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/2 "2025-08-23T10:19:39Z")

</div>

The first question will be:

Is your Node-red exposed to the internet directly?

Can external sites access your computer's node-red?

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 10:20 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/3 "2025-08-23T10:20:45Z")

</div>

No it is not exposed to the internet. Only with VPN I can access it from my phone. But normal use are the devices on the LAN of my home.

PS: Furthermore contrary to what I said earlier (because github seem not to returns searches in old commits or whatever), parts of the code appear in a commit of August 22, while the prior commit was August 20. Portainer was updated 2025-08-21 00:02:42

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [23 August 2025 10:56 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/4 "2025-08-23T10:56:49Z")

</div>

Then possibly a hacked GitHub account. You should check the accounts with access, change passwords and require everyone with access to use 2FA.

There are also GitHub Actions you can turn on that will warn of issues in code and dependencies. Also, plenty of settings in GitHub to control the ability to update code.

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 11:01 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/5 "2025-08-23T11:01:34Z")

</div>

I use Github 2FA, I am the only user. It was in a commit I made from my local node-red instance the wrong code was inserted to.  
So a hacked local node-red server I believe (like Portainer) or the browser?  
I see no sign to a hacked github account. Also because I push and don’t pull code from the repo.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [23 August 2025 11:27 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/6 "2025-08-23T11:27:29Z")

</div>

We have most frequently seen reports where Node-red was accessible from the internet (by port-forwarding) and was the point of access into the system.

Whatever happened in your case, you should regard that entire machine as compromised, though no doubt Docker limits their access.

Indeed be suspicious of every machine on the network, including your router.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [23 August 2025 11:47 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/7 "2025-08-23T11:47:51Z")

</div>

Is it possible before you put it behind a VPN you exposed it to the internet (for test/trial purposes), even if only for a short while?

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 12:05 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/8 "2025-08-23T12:05:10Z")

</div>

Node-red never has been exposed to internet.  
I rather had that as cause, so I knew the issue. Now I have to take into account the PI-server or another LAN-device is hacked too.

At this moment I guess tab 1 was inserted between August 20, 21:09 and August 22, 16:42. I guess tab 2 was inserted maybe while I was editing today. It seems to be a variant of the same code. Maybe I interrupted the editing so it errored on deploy, attracting my attention.  
But editing flows.json outside node-red, just editing the file is not very complex. The first tab was added to the end of flows.json, not proofing anything but it gave me the thought of being an option

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 12:10 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/9 "2025-08-23T12:10:53Z")

</div>

> [@jbudd](#):
>
> though no doubt Docker limits their access.

That hints “they” don’t have access to the server, otherwise alternatives for this route (via node-red) to get shell access would be more appropriate.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [23 August 2025 12:21 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/10 "2025-08-23T12:21:20Z")

</div>

What third party nodes have you installed? You can check in Manage Palette. It is conceivable that one of those is the source.

---

<div class="post-metadata">

**Author:** ![AllanOricil](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/allanoricil/32/106911_2.png) [@AllanOricil](https://discourse.nodered.org/u/AllanOricil)\
**Post date:** [23 August 2025 12:23 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/11 "2025-08-23T12:23:16Z")

</div>

Check if you updated any of your flow dependencies. It is possible that one of your dependencies added a postinstall script that added the changes to your flow.json

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 12:55 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/12 "2025-08-23T12:55:14Z")

</div>

No recent changes. Latest installed dependency - which code I reviewed before installing - is

- node-red-contrib-sse-client

Two dependencies that have a reverse proxy port, running longer than a year. Both use custom ports, but obscurity is no security! :

- node-red-contrib-homeconnect
- node-red-contrib-telegrambot

No custom dependencies, etc.

---

<div class="post-metadata">

**Author:** ![AllanOricil](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/allanoricil/32/106911_2.png) [@AllanOricil](https://discourse.nodered.org/u/AllanOricil)\
**Post date:** [23 August 2025 13:26 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/13 "2025-08-23T13:26:53Z")

</div>

You have to check the whole dependency graph, and not only direct dependencies.

There was an attack in linux a once that was caused by an indirect dependency.

[https://www.akamai.com/blog/security-research/critical-linux-backdoor-xz-utils-discovered-what-to-know](https://www.akamai.com/blog/security-research/critical-linux-backdoor-xz-utils-discovered-what-to-know)

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 13:38 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/14 "2025-08-23T13:38:43Z")

</div>

I agree that all dependencies including indirect independencies can be the source. I scanned node\_modules to start with. you will not expect me to check the whole linux stack. What can I practically do?  
I use very known primary dependencies, so this post was also to view whether more people have the same issue.

---

<div class="post-metadata">

**Author:** ![AllanOricil](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/allanoricil/32/106911_2.png) [@AllanOricil](https://discourse.nodered.org/u/AllanOricil)\
**Post date:** [23 August 2025 14:00 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/15 "2025-08-23T14:00:42Z")

</div>

Buy flowfuse license and delegate security to their team

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 14:03 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/16 "2025-08-23T14:03:11Z")

</div>

😘 Employee?

---

<div class="post-metadata">

**Author:** ![AllanOricil](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/allanoricil/32/106911_2.png) [@AllanOricil](https://discourse.nodered.org/u/AllanOricil)\
**Post date:** [23 August 2025 14:10 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/17 "2025-08-23T14:10:23Z")

</div>

Nope. I just think that if you don't want to take care of your servers security it is better to pay someone to do that.

---

<div class="post-metadata">

**Author:** ![Bolukan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bolukan/32/77991_2.png) [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Post date:** [23 August 2025 14:19 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/18 "2025-08-23T14:19:27Z")

</div>

I take care and I want to take care.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [23 August 2025 14:29 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/19 "2025-08-23T14:29:42Z")

</div>

Since (I believe) that is an Amazon ip address should this be reported to them?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [23 August 2025 14:34 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799/20 "2025-08-23T14:34:31Z")

</div>

> [@Bolukan](#):
>
> this post was also to view whether more people have the same issue.

It is certainly a new one on me, and (I think) more sophisticated than the usual attacks we see.

Could this be a targeted attack on your system?

In your situation I think I would disconnect everything from the internet and make sure that I have good offline backups, in case this is an attempt at a ransomeware attack.

[Next page](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799.md?page=2)
